在SEPolicy中添加新服务遇libsepol.check_assertions断言失败求助
我之前也碰到过完全一样的问题,咱们先把问题根源理清楚,再一步步解决:
问题重现
你在添加自定义verifyusb.sh服务的过程中,先是遇到了verifyusb_exec需要关联system_file_type的错误,添加该属性后又触发了SEPolicy的neverallow断言失败,核心错误提示如下:
libsepol.report_failure: neverallow on line 1029 of system/sepolicy/public/domain.te (or line 14463 of policy.conf) violated by allow verifyusb verifyusb_exec:file { read getattr map execute entrypoint open };
问题根源
这个neverallow是SEPolicy的核心安全限制:自定义domain(你创建的verifyusb)不允许执行带有system_file_type属性的可执行文件。system_file_type是为系统核心二进制文件(比如/system/bin下的原生系统工具)设计的属性,自定义脚本放在/system/bin并添加该属性,直接触碰了安全检查规则。
解决方案(优先推荐方案1)
方案1:将脚本移至/vendor/bin或/product/bin目录
这是最合规的处理方式,/vendor和/product分区是厂商自定义内容的专属分区,不需要system_file_type属性,能完美避开neverallow限制:
修改脚本拷贝路径
调整构建文件(比如Android.mk)中的拷贝规则:LOCAL_DEVICE_MEDIA := device/xxx/XXX/verifyusb.sh:vendor/bin/verifyusb.sh如果是用
product分区,就改成product/bin/verifyusb.sh更新init.rc中的启动路径
修改init.rc里的执行命令,对应新的脚本路径:on boot exec - root root system readproc -- /vendor/bin/verifyusb.sh修正file_contexts配置
在device/xxx/xxx/sepolicy/xxx/file_contexts中更新路径匹配规则:/vendor/bin/verifyusb.sh u:object_r:verifyusb_exec:s0恢复verifyusb.te的定义
去掉之前添加的system_file_type属性,回到初始的合规定义:type verifyusb, domain; type verifyusb_exec, exec_type, file_type; init_daemon_domain(verifyusb)
方案2:若必须放在/system/bin下(不推荐)
如果因为特殊需求必须保留在/system/bin,可以添加neverallow的例外规则,但这会降低系统安全性,仅作为临时应急方案:
在verifyusb.te中添加例外声明:
type verifyusb, domain; type verifyusb_exec, system_file_type, exec_type, file_type; init_daemon_domain(verifyusb) # 添加例外,绕过domain.te中的neverallow限制 neverallow_exceptions verifyusb verifyusb_exec:file { execute entrypoint read getattr map open };
验证步骤
修改完所有配置后,清理旧编译产物再重新编译:
make clean && make -j$(nproc)
内容的提问来源于stack exchange,提问作者GNK

